Recommended Posts

  On 23/03/2010 at 23:29, sc302 said:

download and double click.....I didn't think I needed to give instructions on this.

on my pc it opens but not on the laptop it comes up with the open with window!

  On 23/03/2010 at 23:43, Hazardous Pain said:

on my pc it opens but not on the laptop it comes up with the open with window!

scr is a screen saver file that windows natively knows how to open..... but here is a pif. http://www.forospyware.com/sUBs/dds or .com http://download.bleepingcomputer.com/sUBs/dds.com

she was using Avira antivir until yesterday but then bought an eset smart security liscence! I did a scan using the latter and found some worms but nothing serious!

oh yes there is also this error message which was not there yesterday: DLL<D:\stdplugs\DxPlugins\DxDDS.bmi failed to initialize error code 998. access to this placement of memory is not valid.

Here is the DDS report:

DDS (Ver_10-03-17.01) - NTFSx86

Run by Zouba at 9:46:55,56 on 24/03/2010

Internet Explorer: 8.0.6001.18882 BrowserJavaVersion: 1.6.0_13

Microsoft? Windows Vista™ ?dition Int?grale 6.0.6002.2.1252.33.1036.18.2046.879 [GMT 1:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\System32\svchost.exe -k Cognizance

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\SLsvc.exe

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\rundll32.exe

C:\Program Files\Stardock\Object Desktop\WindowBlinds\vistasrv.exe

C:\Program Files\Stardock\Object Desktop\WindowBlinds\WBVista.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Windows\system32\svchost.exe -k bthsvcs

C:\Windows\system32\drivers\CDAC11BA.EXE

C:\Program Files\ESET\ESET Smart Security\ekrn.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

D:\mentalray\satellite\raysat_3dsmax9_32server.exe

C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files\CyberLink\Shared files\RichVideo.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

C:\Windows\RtHDVCpl.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\ESET\ESET Smart Security\egui.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE

C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe

C:\Windows\system32\wuauclt.exe

C:\Windows\system32\SearchProtocolHost.exe

D:\3dsmax.exe

C:\Users\Zouba\AppData\Local\Temp\AdskCleanup.0001

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Users\Zouba\Downloads\dds.com

C:\Users\Zouba\Downloads\dds.com

C:\Windows\system32\conime.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/

uInternet Settings,ProxyOverride = local

BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files\adobe\/Adobe Contribute CS4/contributeieplugin.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: VeriSoft Access Manager: {df21f1db-80c6-11d3-9483-b03d0ec10000} - c:\program files\bioscrypt\verisoft\bin\ItIEAddIn.dll

BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll

TB: TV5 - Dictionnaires: {cedda62d-5fbe-4ab2-ae2e-5e069f444444} - c:\program files\mediadico\dico tv5\MDTV5TB.dll

TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll

TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\/Adobe Contribute CS4/contributeieplugin.dll

uRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun

uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"

uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun

uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe

mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe

mRun: [RtHDVCpl] RtHDVCpl.exe

mRun: [CognizanceTS] rundll32.exe c:\progra~1\bioscr~1\verisoft\bin\ASTSVCC.dll,RegisterModule

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [<NO NAME>]

mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice

mRunOnce: [NCInstallQueue] rundll32 netman.dll,ProcessQueue

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\bttray.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe

mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: Ajouter la cible du lien ? un fichier PDF existant - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Ajouter ? un fichier PDF existant - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convertir au format Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html

IE: Convertir la cible du lien au format Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000

IE: Envoyer au p?riph?rique &Bluetooth... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm

IE: Envoyer l'ℑ au p?riph?rique Bluetooth... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm

IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll

Notify: WBSrv - c:\program files\stardock\object desktop\windowblinds\wbsrv.dll

AppInit_DLLs: APSHook.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll

STS: Windows DreamScene: {e31004d1-a431-41b8-826f-e902f9d95c81} - %SystemRoot%\System32\DreamScene.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

LSA: Notification Packages = scecli ASWLNPkg

mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

================= FIREFOX ===================

FF - ProfilePath - c:\users\zouba\appdata\roaming\mozilla\firefox\profiles\lnh0l7cs.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q={searchTerms}

FF - prefs.js: browser.search.selectedEngine - Hotspot Shield Customized Web Search

FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1561552&SearchSource=13

FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir=2706&query=

FF - component: c:\users\zouba\appdata\roaming\mozilla\firefox\profiles\lnh0l7cs.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\FFExternalAlert.dll

FF - component: c:\users\zouba\appdata\roaming\mozilla\firefox\profiles\lnh0l7cs.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\RadioWMPCore.dll

FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll

FF - plugin: c:\program files\microsoft\office live\npOLW.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll

FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----

FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256]

R2 ASBroker;Courtier de session de connexion;c:\windows\system32\svchost.exe -k Cognizance [2009-3-24 21504]

R2 ASChannel;Canal de communication local;c:\windows\system32\svchost.exe -k Cognizance [2009-3-24 21504]

R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2009-5-14 731840]

R2 epfwwfp;epfwwfp;c:\windows\system32\drivers\epfwwfp.sys [2009-5-14 38240]

S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\common files\adobe\adobe version cue cs4\server\bin\VersionCueCS4.exe [2008-8-15 284016]

S3 FontCache;Service de cache de police Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-3-24 21504]

============== File Associations ===============

.scr=

=============== Created Last 30 ================

2010-03-23 20:27:51 0 d-----w- c:\program files\ESET

2010-03-23 14:42:30 0 d-----w- c:\program files\Trend Micro

2010-03-22 16:54:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-03-22 16:54:39 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-03-22 16:54:39 0 d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-03-22 15:25:03 0 d-----w- c:\users\zouba\Bluetooth Software

2010-03-21 12:14:20 24064 ----a-w- c:\windows\system32\nshhttp.dll

2010-03-21 12:14:16 411648 ----a-w- c:\windows\system32\drivers\http.sys

2010-03-21 12:14:15 30720 ----a-w- c:\windows\system32\httpapi.dll

2010-03-20 22:37:18 0 ----a-w- c:\windows\system32\cd.dat

2010-03-20 20:56:47 0 d-----w- c:\program files\Conduit

2010-03-20 20:54:27 0 d-----w- C:\Hotspot Shield

2010-03-20 18:27:19 0 d-----w- c:\users\zouba\dwhelper

2010-03-08 17:04:00 0 d-----w- c:\program files\Chaos Group

2010-02-24 10:59:26 2048 ----a-w- c:\windows\system32\tzres.dll

2010-02-24 10:59:06 471552 ----a-w- c:\windows\system32\secproc_isv.dll

2010-02-24 10:59:05 471552 ----a-w- c:\windows\system32\secproc.dll

2010-02-24 10:59:04 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe

2010-02-24 10:59:03 518144 ----a-w- c:\windows\system32\RMActivate.exe

2010-02-24 10:59:03 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe

2010-02-24 10:59:03 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe

2010-02-24 10:59:02 332288 ----a-w- c:\windows\system32\msdrm.dll

2010-02-24 10:59:02 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll

2010-02-24 10:59:02 152064 ----a-w- c:\windows\system32\secproc_ssp.dll

2010-02-24 10:58:58 1696256 ----a-w- c:\windows\system32\gameux.dll

2010-02-24 10:58:57 28672 ----a-w- c:\windows\system32\Apphlpdm.dll

2010-02-24 10:58:56 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll

==================== Find3M ====================

2010-03-24 08:08:59 88947 ----a-w- c:\programdata\nvModes.dat

2010-03-23 20:29:39 51200 ----a-w- c:\windows\inf\infpub.dat

2010-03-23 20:29:39 143360 ----a-w- c:\windows\inf\infstrng.dat

2010-03-23 20:29:38 86016 ----a-w- c:\windows\inf\infstor.dat

2010-03-23 19:52:00 716446 ----a-w- c:\windows\system32\perfh00C.dat

2010-03-23 19:52:00 144386 ----a-w- c:\windows\system32\perfc00C.dat

2010-03-23 15:16:19 6396 ----a-w- c:\windows\bthservsdp.dat

2010-01-02 06:38:20 916480 ----a-w- c:\windows\system32\wininet.dll

2010-01-02 06:32:33 71680 ----a-w- c:\windows\system32\iesetup.dll

2010-01-02 06:32:33 109056 ----a-w- c:\windows\system32\iesysprep.dll

2010-01-02 04:57:00 133632 ----a-w- c:\windows\system32\ieUnatt.exe

2009-11-18 12:04:52 665600 ----a-w- c:\windows\inf\drvindex.dat

2009-03-24 14:19:32 174 --sha-w- c:\program files\desktop.ini

2006-11-02 16:00:48 37390 ----a-w- c:\windows\inf\perflib\040c\perfd.dat

2006-11-02 16:00:48 37390 ----a-w- c:\windows\inf\perflib\040c\perfc.dat

2006-11-02 16:00:48 340236 ----a-w- c:\windows\inf\perflib\040c\perfi.dat

2006-11-02 16:00:48 340236 ----a-w- c:\windows\inf\perflib\040c\perfh.dat

2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat

2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat

2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat

2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat

2009-11-16 13:03:24 245760 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat

2009-10-26 18:35:57 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat

2006-05-03 10:06:54 163328 --sh--r- c:\windows\system32\flvDX.dll

2007-02-21 11:47:16 31232 --sh--r- c:\windows\system32\msfDX.dll

2008-03-16 13:30:52 216064 --sh--r- c:\windows\system32\nbDX.dll

2009-10-11 12:24:52 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012009101120091012\index.dat

2009-04-21 12:05:11 16384 --sha-w- c:\windows\temp\cookies\index.dat

2009-04-21 12:05:11 16384 --sha-w- c:\windows\temp\fichiers internet temporaires\content.ie5\index.dat

2009-04-21 12:05:11 16384 --sha-w- c:\windows\temp\history\history.ie5\index.dat

============= FINISH: 9:49:06,41 ===============

Attach.zipFetching info...

I went through looking at your log and your system info. This is what I would do in your case, if it were never an issue before and "it just started happening":

Start by freeing up some more space on the C: drive get it above 10% above 20% would be nice or use a partition management utility to move some free space to the c partition. Defrag your hard drive, either use the windows defrag or use defraggler http://www.defraggler.com. You have windows vista, so it will manage memory just fine with the default settings.

If by defragging doesnt work, which I think it will, disable windows blinds. What is the deal with all of the nokia stuff? There seems to be a lot of miscellaneous software loaded on the system, you may want to get rid of it, ie. ma-config.com, registrybooster, spywareblaster, you have adobe cs3 and cs4 loaded on, acrobat pro and acrobat reader (pick one),etc. this system is a disaster.

I am not 100% sure of this file: c:\windows\system32\nbDX.dll

Are you using the default render engine in 3DS Max ??? there are other rendering engines for Max that are faster...

I usually use Mental Ray - http://www.mrcad.com/mental-ray?-37-autodesk-3ds-max-2010/

thanks guys for your useful replies!

sc302: yes it's a very messed up system I don't know why she loaded all that :s as for nbDX it looked suspecious to me too and when you confirmed my doubts I googled it and found it to be a malware :s but the weird thing is that malwarebytes didn't see it! when I scanned the pc with eset it found 56 infections this boggled my mind! I've already done a defragmentation! As for nokia staff, she has one and installed everything from the cd!

@Sulphy yes she's using the default render engine, I will tell her to try Mental Ray as you suggested!! thanks for the tip :) and since you're a 3DS user, do you have any idea about this error message at the launching of the program? DLL<D:\stdplugs\DxPlugins\DxDDS.bmi failed to initialize error code 998. access to this placement of memory is not valid.

and thanks in advance for your valuable help :) very appreciated

  On 24/03/2010 at 22:21, Hazardous Pain said:

thanks guys for your useful replies!

sc302: yes it's a very messed up system I don't know why she loaded all that :s as for nbDX it looked suspecious to me too and when you confirmed my doubts I googled it and found it to be a malware :s but the weird thing is that malwarebytes didn't see it! when I scanned the pc with eset it found 56 infections this boggled my mind! I've already done a defragmentation! As for nokia staff, she has one and installed everything from the cd!

@Sulphy yes she's using the default render engine, I will tell her to try Mental Ray as you suggested!! thanks for the tip :) and since you're a 3DS user, do you have any idea about this error message at the launching of the program? DLL<D:\stdplugs\DxPlugins\DxDDS.bmi failed to initialize error code 998. access to this placement of memory is not valid.

and thanks in advance for your valuable help :) very appreciated

Mental Ray won't be faster. It might be better if she learns to use it. MR is however horrible at handlgin large textures and becomes slower than rendering Avatar on a 286 :p

MR of the advanced renderers has the advantage of being included with MAX though. I think there's a free version of Brazil though. all advanced renderers will generally be slower than Scanline though(wich isn't really fully scanline anymore). they can just do some more neat rendering tricks to make their stuff look better.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.